WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 404 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High Travelpayouts Plugin travelpayouts Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.1.13 Fixed in 1.1.13 CVE-2023-5934 WPScan
4.8 Medium Travelpayouts Plugin travelpayouts Cross-Site Scripting Reflected XSS < 1.1.14 Fixed in 1.1.14 CVE-2023-5932 WPScan
2.7 Low ApplyOnline – Application Form Builder and Manager Plugin apply-online Broken Access Control Application Form Builder and Manager < 2.6.3 - Unauthenticated Application File Access < 2.6.3 Fixed in 2.6.3 CVE-2024-10098 WPScan
5.9 Medium Color Your Bar Plugin color-your-bar Cross-Site Scripting ≤ 2.0 CVE-2025-47595 Patchstack
7.3 High LayoutBoxx Plugin layoutboxx Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.3.1 CVE-2025-2802 Wordfence
7.5 High Mayosis Core Plugin Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 5.4.1 CVE-2025-1565 Wordfence
5.9 Medium COVID-19 (Coronavirus) Update Your Customers Plugin covid-19-alert Cross-Site Scripting ≤ 1.5.1 CVE-2025-46523 Patchstack
7.5 High Capturly Plugin capturly-optimize-your-website Local File Inclusion No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-39379 Patchstack
7.1 High WPYog Documents Plugin wpyog-documents Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-27292 Patchstack
5.3 Medium Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products Plugin password-protected Information Disclosure Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.7.7 CVE-2025-3453 Wordfence
6.5 Medium DSGVO Youtube Plugin dsgvo-youtube Cross-Site Scripting ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-26982 Patchstack
7.1 High Lock Your Updates Plugin lock-your-updates Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-32537 Patchstack
7.1 High Workbox Video from Vimeo & Youtube Plugin workbox-video-from-vimeo-youtube-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.2 CVE-2025-32534 Patchstack
5.9 Medium YouTube Embed Plugin youtube-embed Cross-Site Scripting ≤ 5.3.1 Fixed in 5.4 CVE-2025-31008 Patchstack
5.3 Medium WP Genealogy – Your Family History Website Plugin wpgenealogy Broken Access Control No login needed ≤ 0.1.9 CVE-2025-32252 Patchstack
6.5 Medium Video Playlist For YouTube Plugin video-playlist-for-youtube Cross-Site Scripting ≤ 6.7.1 CVE-2025-32183 Patchstack
6.5 Medium Planyo online reservation system Plugin planyo-online-reservation-system Cross-Site Scripting ≤ 3.1 CVE-2025-31811 Patchstack
6.5 Medium Lightweight and Responsive Youtube Embed Plugin lightweight-and-responsive-youtube-embed Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-31744 Patchstack
6.5 Medium Lightweight and Responsive Youtube Embed Plugin lightweight-and-responsive-youtube-embed Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-31743 Patchstack
6.5 Medium YouTube SimpleGallery Plugin youtube-simplegallery Cross-Site Scripting ≤ 2.0.6 CVE-2025-31453 Patchstack
7.1 High Are you robot google recaptcha Plugin are-you-robot-recaptcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-28928 Patchstack
7.1 High Your Lightbox Plugin your-lightbox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23704 Patchstack
6.4 Medium Your Simple SVG Support Plugin your-simple-svg-support Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.1 CVE-2025-2542 Wordfence
4.7 Medium CryoKey Plugin cryokey Cross-Site Scripting Reflected Cross-Site Scripting via 'ckemail' Parameter No login needed ≤ 2.4 CVE-2025-2477 Wordfence
5.3 Medium VidoRev Extensions Plugin Broken Access Control Missing Authorization to Unauthenticated Youtube Video Import No login needed ≤ 2.9.9.9.9.9.5 CVE-2025-0955 Wordfence
7.1 High WP Find Your Nearest Plugin wp-find-your-nearest Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 0.3.1 CVE-2025-25161 Patchstack
4.4 Medium Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site Plugin counter-box Cross-Site Scripting Authenticated (Administrator+) DOM-Based Stored Cross-Site Scripting ≤ 2.0.6 CVE-2024-13901 Wordfence
6.3 Medium PixelYourSite Plugin pixelyoursite PHP Object Injection Insecure deserialization No login needed 10.1.1.1 CVE-2025-0769 Fluid Attacks
4.3 Medium NextMove Lite – Thank You Page for WooCommerce Plugin woo-thank-you-page-nextmove-lite Broken Access Control Thank You Page for WooCommerce <= 2.19.0 - Missing Authorization to Authenticated (Subscriber+) Deactivation Reason Submission ≤ 2.19.0 CVE-2024-10860 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.0.0.1 CVE-2025-1513 Wordfence
6.4 Medium YouTube Playlists with Schema Plugin jma-youtube-playlists-with-schema Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.1 CVE-2024-13589 Wordfence
6.4 Medium Web Stories Enhancer – Level Up Your Web Stories Plugin web-stories-enhancer Cross-Site Scripting Level Up Your Web Stories <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3 CVE-2024-13575 Wordfence
6.1 Medium magayo Lottery Results Plugin magayo-lottery-results Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.0.12 CVE-2024-13522 Wordfence
7.1 High QMean – WordPress Did You Mean Plugin qmean Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-23428 Patchstack
5.9 Medium Elfsight Yottie Lite Plugin yottie-lite Cross-Site Scripting ≤ 1.3.3 CVE-2025-26561 Patchstack
4.3 Medium Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time Plugin builder-shortcode-extras Information Disclosure WordPress Shortcodes Collection to Save You Time <= 1.0.0 - Authenticated (Contributor+) Post Disclosure ≤ 1.0.0 CVE-2024-13841 Wordfence
5.4 Medium Traveler Layout Essential For Elementor Plugin traveler-layout-essential-for-elementor Server-Side Request Forgery No login needed ≤ 1.4 Fixed in 1.4 CVE-2025-22701 Patchstack
6.5 Medium Demo User DZS Plugin demo-user-dzs-showcase-your-admin-safely Cross-Site Scripting ≤ 1.1.0 CVE-2025-23581 Patchstack
6.4 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.8.24 CVE-2024-13470 Wordfence
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
7.1 High Passwordless WP – Login with your glance or fingerprint Plugin passwordless-wp Cross-Site Scripting Login with your glance or fingerprint Plugin <= 1.1.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 CVE-2025-23792 Patchstack
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license) ≤ 1.3.3 CVE-2024-13370 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 1.3.4 CVE-2024-13368 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion ≤ 1.3.2 CVE-2024-12113 Wordfence
6.5 Medium Easy YouTube Gallery Plugin easy-youtube-gallery Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.4 Fixed in 1.0.5 CVE-2025-24721 Patchstack
4.3 Medium Attire Blocks Plugin attire-blocks Cross-Site Request Forgery No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-24696 Patchstack
5.9 Medium Auction Nudge – Your eBay on Your Site Plugin auction-nudge Cross-Site Scripting Your eBay on Your Site plugin <= 7.2.0 - Cross Site Scripting (XSS) ≤ 7.2.0 Fixed in 7.2.1 CVE-2025-24658 Patchstack
7.1 High Youtube Video Grid Plugin youmax-channel-embeds-for-youtube-businesses Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2025-23634 Patchstack
4.3 Medium ApplyOnline Plugin apply-online Broken Access Control ≤ 2.6.7.1 Fixed in 2.6.7.2 CVE-2025-22721 Patchstack
5.3 Medium Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Plugin evergreen-content-poster Broken Access Control Auto Post and Schedule Your Best Content to Social Media <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 1.4.4 CVE-2024-12071 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only